Access control method and system for application, device, medium, and program product
Abstract
The present disclosure relates to the field of network technologies and discloses an application access control method and system, and a device, a medium and a program product thereof. The present disclosure provides an application access control method. The method includes: generating, by a security management application client, an access request after detecting access to a target application, and sending the access request to a central domain name system; performing, by the central domain name system, domain name resolution on the access request to obtain a target application domain name of the target application, and sending the target application domain name to an application gateway; and determining, by the application gateway, a target access policy for the target application based on a matching result of the target application domain name in a first configuration file, and controlling, based on the target access policy, a terminal device.
Claims
exact text as granted — not AI-modifiedI/We claim:
1 . An access control method for an application, wherein the method is applied to an access control system, the access control system comprises a security management application client, a security management application server, a central domain name system and an application gateway, and the method comprises:
generating, by the security management application client, a domain name resolution request after detecting an access request from a terminal device where the security management application client is located for a target application, and sending the domain name resolution request to the central domain name system; performing, by the central domain name system, domain name resolution on the domain name resolution request to obtain a target application domain name of the target application, and sending the target application domain name to the application gateway; and determining, by the application gateway, a target access policy for the target application based on a matching result of the target application domain name in a first configuration file, and controlling, based on the target access policy, the terminal device where the security management application client is located to access the target application, wherein the first configuration file is used for characterizing a correspondence between application domain names and access policies, and the first configuration file is provided by the security management application server.
2 . The method according to claim 1 , wherein controlling, by the application gateway and based on the target access policy, the terminal device where the security management application client is located to access the target application comprises:
in response to the target access policy being a first target access policy, sending, by the application gateway, a first access resource to the security management application client to prevent the terminal device from accessing the target application.
3 . The method according to claim 2 , wherein the method further comprises:
sending, by the application gateway, access blocking information to the security management application server to prompt that the terminal device is prevented from accessing the target application; and receiving and saving, by the security management application server, the access blocking information.
4 . The method according to claim 3 , wherein sending, by the application gateway, the access blocking information to the security management application server comprises:
starting, in the application gateway, a timing task according to a preset period, wherein the timing task is a task configured to send the access blocking information to the security management application server at regular intervals.
5 . The method according to claim 1 , wherein controlling, based on the target access policy, the terminal device where the security management application client is located to access the target application comprises:
in response to the target access policy being a second target access policy, sending, by the application gateway, a second access resource to the security management application client to allow the terminal device where the security management application client is located to access the target application.
6 . The method according to claim 5 , wherein controlling, based on the target access policy, the terminal device where the security management application client is located to access the target application further comprises:
determining, in the application gateway, an application access permission of the terminal device where the security management application client is located to access the target application through a preset second configuration file, wherein the second configuration file is used for characterizing a correspondence between a same application and application access permissions of a plurality of security management application clients, and the second configuration file is provided by the security management application server; and controlling, by the application gateway, the terminal device where the security management application client is located to access the target application according to the application access permission.
7 . The method according to claim 5 , wherein the method further comprises:
determining, by the application gateway, a target information acquisition type corresponding to the second target access policy, and acquiring, in a process that the terminal device where the security management application client is located accesses the target application, target access information corresponding to the target application according to the target information acquisition type; sending, by the application gateway, the target access information to the security management application server; and saving, by the security management application server, the received target access information.
8 . The method according to claim 7 , wherein the target information acquisition type is determined by the application gateway through a third configuration file, the third configuration file is used for characterizing a correspondence between a target access policy and an information acquisition type, and the third configuration file is provided by the security management application server.
9 . The method according to claim 1 , wherein the security management application server is connected to the security management application client through a root certificate, and the security management application server is connected to the application gateway through an intermediate certificate, and
the method further comprises: determining, by the security management application server, the first configuration file through a corresponding management platform, and sending the first configuration file to the security management application client and the application gateway respectively, wherein the first configuration file comprises an application domain name set, and the application domain name set comprises application domain names of a plurality of applications and corresponding wildcard domain names; and generating, by the security management application client, the domain name resolution request after detecting the access request from the terminal device where the security management application client is located for the target application comprises: determining, in the security management application client, a target application domain name of an application to be accessed after detecting an access request initiated by the terminal device where the security management application client is located; in response to an application domain name or a wildcard domain name matching with the target application domain name being matched in the application domain name set, determining that the application to be accessed is the target application, and generating the domain name resolution request, wherein the target application is an application corresponding to the application domain name or the wildcard domain name matching with the target application domain name; and in response to the application domain name or the wildcard domain name matching with the target application domain name being not matched in the application domain name set, determining that the application to be accessed is a non-target application, and generating access prompt information to be displayed on the terminal device where the security management application client is located to prompt that the access request is an invalid request.
10 . The method according to claim 9 , wherein the process of sending, by the security management application client, the domain name resolution request to the central domain name system comprises:
creating, in the security management application client, a mirror file of the domain name resolution request; and sending, the mirror file to the central domain name system.
11 . An access control system, comprising:
a security management application client, configured to generate a domain name resolution request after detecting an access request from a terminal device where the security management application client is located for a target application, and send the domain name resolution request to a central domain name system; the central domain name system, configured to perform domain name resolution on the domain name resolution request to obtain a target application domain name of the target application, and send the target application domain name to an application gateway; the application gateway, configured to receive the target application domain name, determine, based on a matching result of the target application domain name in a first configuration file, a target access policy for the target application, and control, based on the target access policy, the terminal device where the security management application client is located to access the target application, wherein the first configuration file is used for characterizing a correspondence between application domain names and access policies, and the first configuration file is provided by a security management application server; and the security management application server, configured to store the first configuration file.
12 . The system according to claim 11 , wherein the application gateway is further configured to:
in response to the target access policy being a first target access policy, send a first access resource to the security management application client to prevent the terminal device from accessing the target application.
13 . The system according to claim 12 , wherein the system is further configured to:
send, by the application gateway, access blocking information to the security management application server to prompt that the terminal device is prevented from accessing the target application; and receive and save, by the security management application server, the access blocking information.
14 . The system according to claim 13 , wherein the application gateway is further configured to:
start, in the application gateway, a timing task according to a preset period, wherein the timing task is a task configured to send the access blocking information to the security management application server at regular intervals.
15 . The system according to claim 11 , wherein the application gateway is further configured to:
in response to the target access policy being a second target access policy, send a second access resource to the security management application client to allow the terminal device where the security management application client is located to access the target application.
16 . The system according to claim 15 , wherein the application gateway is further configured to:
determine, in the application gateway, an application access permission of the terminal device where the security management application client is located to access the target application through a preset second configuration file, wherein the second configuration file is used for characterizing a correspondence between a same application and application access permissions of a plurality of security management application clients, and the second configuration file is provided by the security management application server; and control the terminal device where the security management application client is located to access the target application according to the application access permission.
17 . The system according to claim 15 , wherein the system is further configured to:
determine, by the application gateway, a target information acquisition type corresponding to the second target access policy, and acquire, in a process that the terminal device where the security management application client is located accesses the target application, target access information corresponding to the target application according to the target information acquisition type; send, by the application gateway, the target access information to the security management application server; and save, by the security management application server, the received target access information.
18 . The system according to claim 17 , wherein the target information acquisition type is determined by the application gateway through a third configuration file, the third configuration file is used for characterizing a correspondence between a target access policy and an information acquisition type, and the third configuration file is provided by the security management application server.
19 . The system according to claim 11 , wherein the security management application server is connected to the security management application client through a root certificate, and the security management application server is connected to the application gateway through an intermediate certificate, and
the system is further configured to: determine, by the security management application server, the first configuration file through a corresponding management platform, and send the first configuration file to the security management application client and the application gateway respectively, wherein the first configuration file comprises an application domain name set, and the application domain name set comprises application domain names of a plurality of applications and corresponding wildcard domain names; and generate, by the security management application client, the domain name resolution request after detecting the access request from the terminal device where the security management application client is located for the target application comprises: determining, in the security management application client, a target application domain name of an application to be accessed after detecting an access request initiated by the terminal device where the security management application client is located; in response to an application domain name or a wildcard domain name matching with the target application domain name being matched in the application domain name set, determine that the application to be accessed is the target application, and generate the domain name resolution request, wherein the target application is an application corresponding to the application domain name or the wildcard domain name matching with the target application domain name; and in response to the application domain name or the wildcard domain name matching with the target application domain name being not matched in the application domain name set, determine that the application to be accessed is a non-target application, and generate access prompt information to be displayed on the terminal device where the security management application client is located to prompt that the access request is an invalid request.
20 . A non-transitory storage medium containing computer-executable instructions, wherein the computer-executable instructions, when executed by an access control system, the access control system comprises a security management application client, a security management application server, a central domain name system and an application gateway, are used to cause the access control system to:
generate, by the security management application client, a domain name resolution request after detecting an access request from a terminal device where the security management application client is located for a target application, and send the domain name resolution request to the central domain name system;
perform, by the central domain name system, domain name resolution on the domain name resolution request to obtain a target application domain name of the target application, and sending the target application domain name to the application gateway; and
determine, by the application gateway, a target access policy for the target application based on a matching result of the target application domain name in a first configuration file, and control, based on the target access policy, the terminal device where the security management application client is located to access the target application, wherein the first configuration file is used for characterizing a correspondence between application domain names and access policies, and the first configuration file is provided by the security management application server.Join the waitlist — get patent alerts
Track US2025385916A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.